OWASP Top 10
Le socle minimum.
Injection (SQL, NoSQL, command, LDAP), Broken Access Control (IDOR, role bypass), Crypto Failures, SSRF, Insecure Design, Security Misconfiguration. Revue manuelle ciblée sur les endpoints sensibles + scan Semgrep/CodeQL.